Agent-Driven Attackers Deleted Azure Resources (09/28/2026)

September 28, 2026
Agent-Driven Attackers Deleted Azure Resources (09/28/2026)
Key Intel / TL;DR
  • › JadePuffer used two compromised Azure service principals to target more than 100 storage accounts, Key Vaults, and compute resources in about seven minutes.
  • › Credentials for one of those service principals had appeared in a public GitHub issue before the attack.
  • › Azure resource locks and storage protections stopped some of the deletions, which is the cheapest control in this story.
  • › CISA gave federal agencies until Wednesday to patch the two exploited Citrix NetScaler flaws.
  • › Bitget says its $388 million loss came through a flaw in a third-party security product it used.

The JadePuffer intrusions Microsoft described this week are worth reading for the timeline alone. Once the attacker held two service principals, the destructive phase against more than 100 storage accounts plus vaults and compute ran for about seven minutes, driven by automation instead of an operator at a keyboard. Azure resource locks that somebody had set months earlier stopped part of it, since no alert a human could act on fits inside seven minutes.

Top 5 Critical Security Alerts

1. JadePuffer Destroys Azure Resources With Compromised Service Principals

Microsoft describes the JadePuffer operator, tracked as Storm-3168, using two compromised Azure service principals to run automated reconnaissance, credential theft, and destruction against more than 100 storage accounts as well as Key Vaults, Function Apps, virtual machines, and App Services over roughly seven minutes, per BleepingComputer and The Hacker News. Microsoft could not confirm the entry point, but credentials for one service principal had appeared in a public GitHub issue before the attacks. Some deletions failed because of Azure resource locks and storage-level protections, and attempts to remove Azure Site Recovery locks, a sign of ransomware preparation, also failed, according to Dark Reading and The Register.

Operator Note: Delete locks on production resource groups and immutable storage protections are cheap to turn on and they worked here when nothing else could react in time. Pair them with a search of public repositories and issue trackers for your own service principal secrets.

2. CISA Gives Agencies Until Wednesday on Citrix NetScaler

CISA added the two exploited NetScaler flaws, CVE-2026-88771 and CVE-2026-88772, to its catalog on Sunday and ordered federal agencies to patch by Wednesday, per BleepingComputer and The Hacker News. Agencies in the Netherlands, the US, and the UK issued advisories on Sunday after responders began warning on Saturday, and Citrix confirmed eight new vulnerabilities in total, according to The Record and Sophos. Our Sunday briefing has the affected configurations and fixed builds.

3. Bitget Traces Its $388 Million Loss to a Third-Party Security Product

Bitget said the attacker who took about $388 million got in through a vulnerability in a third-party security product the exchange used, per The Hacker News. The exchange has since restarted Bitcoin withdrawals, per BleepingComputer.

Operator Note: Security products run with some of the highest privileges in any environment, which makes them an entry point worth the same scrutiny as anything else you expose. Know which of yours are internet-facing and how fast their vendor ships fixes.

4. Apple Patches an Exploited Flaw in Older iOS and macOS

Apple patched CVE-2026-86950, which it said may have been exploited in an extremely sophisticated attack against specific individuals on versions before iOS 27, with fixes for iOS 26, macOS 26, and macOS 15, per the SANS Internet Storm Center and The Hacker News. The current 27 releases are not affected, so the exposure sits on every device your people have not upgraded.

5. More Than 16,000 Supabase Databases Expose Personal Data

Researchers found more than 16,000 misconfigured Supabase databases with readable tables containing personal information, passwords, or authentication tokens, per BleepingComputer. Many are apps built quickly, often with AI assistance, by people who never locked down who can read each table.

Additional Security Alerts

Threat Intelligence

  • Carbonato botnet installs an AI agent on hijacked Docker hosts: The botnet deploys the open-source Hermes agent framework, controlled through Telegram, and steals AI API keys from exposed Docker daemons. The Hacker News
  • OpenAI’s agents used a Google security training game as a relay: New details show agents hit a UN trade statistics API roughly 16,500 times, routing around restrictions through a web security learning game. The Decoder
  • Microsoft details NeedyMantis: A modular post-compromise framework used to keep long-term access in targeted intrusions. Microsoft Security
  • RatHat’s Android banking console uses Gemini to rank victims: Cleafy traced nearly 100 deployments of a console that uses AI to pick higher-value targets. The Hacker News
  • Schneier clarifies the RSA attack reported last week: The technique is a 2007 forgery attack newly implemented, and it does not factor keys. Schneier on Security

Security Breaches & Incidents

  • FBI reportedly tells agents their data was stolen: The bureau has told agents their personal information and Social Security numbers were exposed, and ShinyHunters told 404 Media it will not publish the data. TechCrunch, 404 Media
  • Dutch police confirm a ShinyHunters arrest: A man arrested in Amsterdam earlier this month was detained as part of the investigation. BleepingComputer, Krebs on Security
  • Times Car confirms 6.6 million accounts compromised: The Japanese car-sharing service confirmed the scale of last week’s attack. BleepingComputer
  • Ransomware disrupts Japanese railway operator Keio: The attack over the weekend hit some business systems. BleepingComputer

Cloud & Network Security

  • One packet can crash TDengine servers in industrial environments: A high-severity zero-day affects the time-series database used across industrial, energy, and automotive systems. Dark Reading
  • A spyware ad blocker stays in the Chrome Web Store: Poper Blocker exfiltrates sensitive data from millions of users despite researcher warnings. Dark Reading
  • AI logins from more than 80,000 organizations sit in stealer logs: Stolen credentials and sessions for AI accounts are feeding stolen conversations and LLMjacking. BleepingComputer

The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.

Distribute Intel
Chris Armour
Director of Information Security
Chris Armour
The Breaker & Builder.

Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.

View Profile →
Press & Media

Media Inquiries

For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.

Initialize Terminal

Initiate
Deployment.

Whether you need a full adversarial facility audit or an executive resilience protocol for your leadership team.

Secure the Facility (Assessments)
Secure the Mind (Coaching/Speaking)